CRA incident & vulnerability reporting applies from 11 September 2026 — including products already on the EU market.
For makers of software and connected products sold into the EU

When the 24-hour clock starts, you won't have time to figure out the process. Have it on the shelf.

From 11 September 2026, the EU Cyber Resilience Act requires manufacturers to file an early warning within 24 hours of learning about an actively exploited vulnerability or severe incident, a fuller report at 72 hours, and a final report after that. The EU's own SME survey says practical templates are the #1 thing companies are missing — and they haven't been provided. This pack is those templates.

24hearly warning
72hnotification
14d / 1mofinal report
Get the pack — $390 Instant download · 14-day unconditional refund · includes the Dec 2027 documentation roadmap

Who this hits (it's broader than most teams think)

Software with EU users"Products with digital elements" covers software placed on the EU market — not just IoT hardware. The pack's triage tells you in minutes whether and how you're in scope.
Products you already shippedThe September reporting duty attaches to products on the market today. There is no grandfathering to hide behind.
Non-EU makersSelling into the EU puts you in scope wherever you're incorporated — and your EU importers and distributors are about to start asking for your paperwork anyway.
Small teams without a compliance personThe obligations assume someone knows the process. The pack IS the process, written down, with every form pre-structured.

What's in the pack

  • Scope triage — are you a manufacturer, importer, distributor, or open-source steward, and which product class are you in? A 15-minute worksheet with the exclusions mapped.
  • The reporting runbook — the heart of the pack: trigger definitions in plain language, a report/don't-report decision tree with counsel-escalation points, per-stage checklists mapped to ENISA's published field matrix, and the Single-Reporting-Platform registration runbook current to ENISA's 31 July / 3 August guides — EU-Login pre-steps, the primary/backup user flow (and its 7-day invite expiry), the "you can report while validation is pending" rule, plus a contingency route if the platform slips.
  • Coordinated vulnerability disclosure policy — the CVD policy the Act expects, plus security.txt and an intake workflow you can run from a shared inbox.
  • Support-period & end-of-life templates — the determination worksheet and the public statements buyers and surveillance authorities look for.
  • Technical-documentation skeleton — the full Dec 2027 file structure with per-section prompts, so the folder that takes months starts today.
  • SBOM primer — what's expected and how to generate one for npm, pip, cargo, and container stacks.
  • Evidence log + edge-case FAQ — SaaS boundaries, open-source components, upstream suppliers.

PDF + editable filesImporter/distributor annex availableUpdate tracker through Dec 2027

$390 one-off · final weeks before the duty starts

Priced for the last month before 11 September 2026 — rises to $690 once the reporting duty is live. Bundle with the importer/distributor annex for $590. Optional tracker (+$49/mo): reporting-platform go-live alerts, harmonised-standards drops, Dec 2027 milestones. Updated August 2026 against ENISA's newly published reporting-platform guides.

Get the pack — instant download
14-day unconditional refund.

Questions we'd ask too

Is this legal advice or a conformity assessment?

Neither. It's an implementation pack — organized information, templates, and runbooks built from the regulation and official guidance, with citations and dates on every claim. Your counsel and (where required) notified bodies still do their jobs; this makes both dramatically cheaper.

We're tiny. Does the EU really expect this from us?

The reporting duties apply to manufacturers of in-scope products regardless of size — and the EU's own agency documented that SMEs lack exactly these templates. Small teams are who this pack exists for.

Isn't the CRA a 2027 problem?

The full essential requirements land 11 December 2027 — but the reporting duties start 11 September 2026, and they cover products already on sale. The pack handles September now and gives you the 2027 folder structure to grow into.

What if official templates come out later?

Then the tracker folds them in and your process gets even easier — you keep the operational runbook, the policies, and the evidence trail, which official forms don't provide.